A DNS inventory that stays current
Zones and records discovered automatically and kept live, with change history — instead of a spreadsheet that is stale the day after it is written.
Catch misconfigurations before they cause outages
42 built-in rules flag dangling CNAMEs, broken delegations, missing SOA records and orphaned zones.
Close email security gaps
Validation of DKIM, MX and TTL anomalies alongside SPF, DMARC, MTA-STS and TLS-RPT, so missing or malformed authentication records surface immediately. Starter and up.
Certificate and domain expiry warnings
Certificate Transparency monitoring detects newly issued — and unauthorised — certificates for your domains. RDAP monitoring warns you before a registration lapses. Certificate monitoring from Starter, RDAP from Professional.
Alerts that reach the right people — risk-scored
Teams, Slack, email or webhooks, with per-rule routing, weekly digests and suppression during maintenance windows. Every DNS change is scored for risk, so a routine record update and a change that could break mail delivery do not arrive as the same alert. Professional and up.
Read-only and agentless
Consent once, read-only. Nothing runs in your tenant and no record is ever changed.
Platform and cloud operations teams
Own DNS across many subscriptions and need one live view of it.
Security teams
Need email authentication, subdomain takeover exposure and certificate issuance watched continuously rather than audited annually.
Compliance-driven organisations
Need evidence that DNS and email security configuration is reviewed on a schedule (NIS2, ISO 27001, D-mærket). Compliance reports and audit trail export are the relevant hooks.
MSPs and service providers
Manage DNS in customer tenants and want drift and expiry warnings before the customer notices. Setup is per tenant; the Enterprise REST API is the route to aggregation today.
